Security GRC Specialist, IT/Security Risk Management
Wealthsimple
In this role, you'll have the opportunity to Support the end-to-end IT and security risk management lifecycle, including risk identification, assessment, treatment tracking, and reporting
Maintain and continuously improve the enterprise IT/security risk register, ensuring risks are accurately documented, rated, and assigned to appropriate owners
Perform risk assessments across technology domains (cloud infra, access management, application security) and third-party assessments using the appropriate methodology for each
Partner with control owners and business stakeholders to evaluate the effectiveness of risk mitigation controls and identify gaps
Integrate vendor and technology risk findings into the risk register to facilitate tracking and remediation across both IT/Security and Third-Party Risk Management.
Contribute to the development and maintenance of risk policies, standards, and procedures
Assist in preparing risk reporting and dashboards for senior leadership and committee-level audiences
Monitor the threat and vulnerability landscape and help translate emerging risks into actionable insights for the business
Support security and compliance initiatives, including PCI DSS, SOC 2, and NIST, from a risk lens, ensuring risk findings are integrated into broader compliance activities
Participate in risk-related work streams tied to new product launches, infrastructure changes, and strategic initiatives
What you'll bring
3–5 years of experience in IT risk management, information security, or a related GRC function, ideally within financial services or fintech
Solid understanding of IT and security risk frameworks such as NIST CSF, ISO 27001, or FAIR
Familiarity with key technology risk domains including cloud (AWS preferred), identity and access management and vulnerability management
Experience conducting third-party and vendor reviews, with knowledge of due diligence review methodology, is an asset
Experience maintaining risk registers and supporting risk assessment processes
Working knowledge of compliance frameworks such as SOC 2, PCI DSS, and/or NIST is a strong asset
Strong analytical and written communication skills, with the ability to translate technical risk findings into clear business language
Comfortable working cross-functionally with both technical and non-technical stakeholders
Experience with GRC tools and risk management platforms (e.g.Jira, Drata) is an asset
Self-starter who can operate independently, manage competing priorities, and drive work to completion
Relevant certifications are an asset (CRISC, CISA, CISSP, or equivalent)
Support the end-to-end IT and security risk management lifecycle, including risk identification, assessment, treatment tracking, and reporting
Maintain and continuously improve the enterprise IT/security risk register, ensuring risks are accurately documented, rated, and assigned to appropriate owners
Perform risk assessments across technology domains (cloud infra, access management, application security) and third-party assessments using the appropriate methodology for each
Partner with control owners and business stakeholders to evaluate the effectiveness of risk mitigation controls and identify gaps
Integrate vendor and technology risk findings into the risk register to facilitate tracking and remediation across both IT/Security and Third-Party Risk Management.
Contribute to the development and maintenance of risk policies, standards, and procedures
Assist in preparing risk reporting and dashboards for senior leadership and committee-level audiences
Monitor the threat and vulnerability landscape and help translate emerging risks into actionable insights for the business
Support security and compliance initiatives, including PCI DSS, SOC 2, and NIST, from a risk lens, ensuring risk findings are integrated into broader compliance activities
Participate in risk-related work streams tied to new product launches, infrastructure changes, and strategic initiatives
3–5 years of experience in IT risk management, information security, or a related GRC function, ideally within financial services or fintech
Solid understanding of IT and security risk frameworks such as NIST CSF, ISO 27001, or FAIR
Familiarity with key technology risk domains including cloud (AWS preferred), identity and access management and vulnerability management
Experience conducting third-party and vendor reviews, with knowledge of due diligence review methodology, is an asset
Experience maintaining risk registers and supporting risk assessment processes
Working knowledge of compliance frameworks such as SOC 2, PCI DSS, and/or NIST is a strong asset
Strong analytical and written communication skills, with the ability to translate technical risk findings into clear business language
Comfortable working cross-functionally with both technical and non-technical stakeholders
Experience with GRC tools and risk management platforms (e.g.Jira, Drata) is an asset
Self-starter who can operate independently, manage competing priorities, and drive work to completion
Relevant certifications are an asset (CRISC, CISA, CISSP, or equivalent)
$100k - $150k
...Description Recruiter Summary of Position Job Title: Lead Security Compliance Advisor (GRC) Location: Remote within PST/MST/CST/EST time zones... ...-on strategist who thrives on the true substance of risk management. You will spend your days collaborating with client...SuggestedPermanent employmentContract workRemote workShift work- ...offering expertise in property management, investment management,... ...Senior Manager, Information Security GRC owns the strategy, execution,... ...Information Security Governance, Risk, and Compliance program. This... ...to influence partners across IT, Engineering, Legal, Privacy,...SuggestedFull timeContract workWork experience placementLocal areaImmediate startRemote work
- ...development | POSITION SUMMARY –Security Analyst II (Compliance)... ...general supervision of the GRC Manager, this position serves as a Security... ...include providing risk assessment and/or compliance support... ...and provides guidance to other IT staff and non-IT areas on how...SuggestedWork at officeRemote workWork from homeRelocationFlexible hours
$96.56k - $124.96k
...Join Dorsey's Information Security team as a GRC Information Security Systems... ...initiatives across audits, risk, governance, and compliance.... ...Information Security Systems Manager with the maintenance of Information... ..., audit experience and IT/Security technology, software...SuggestedContract workCurrently hiringWork at officeWorldwideFlexible hours- ...solutions. Our solutions are designed and managed to not only reduce costs, but to... ...Position Description: The Information Security Specialist III supports the National Oceanic and Atmospheric... ...Administration (NOAA) Internal Risk Management Program (IRMP), providing advanced...SuggestedFull timeContract workFor contractorsWork at office
- ...Jersey’s Office of the Chief Security Officer (OCSO) leads the protection... ...for designing and managing programs that safeguard the agency... ...Senior Information Security Specialist who wants to make a significant... ...of policy, training, risk and governance frameworks, and...Full timeWork at officeRemote work1 day per week
- ...Join to apply for the 1.20. IT Security Analyst role at Focused HR Solutions . 100% onsite in Richmond, VA. No remote work is allowed... ...Information Security program by providing cybersecurity, risk management, IT infrastructure services and IT governance by working with...Contract workWork at officeRemote work
- ...Job Announcement Acts as an Information Security Analyst within the Information Security... ...cybersecurity, privacy, and technology risk management across the enterprise. This role focuses... ...agency information security coordinators, IT analysts, and external partners regarding...Work at officeRemote work
- ...Exemption Status: Exempt A Brief Overview The System Director of IT Security serves as Stormont Vail Health's Chief Information Security... ...position provides executive leadership for cybersecurity risk management, incident response, security architecture, vendor risk...Remote work
$99k - $225k
...Job Number: R0240861 Information Security Risk Specialist The Opportunity: Conduct security assessments on DoD cloud environments using the Risk Management Framework (RMF).Provide guidance on policies and procedures to ensure compliance within an accreditation...Full timeContract workPart timeWork at officeLocal areaRemote work$106.58k - $177.63k
...We are currently seeking a GRC Security Compliance Advisor to join our... ...and supporting governance, risk, and compliance (GRC) activities... ..., audit readiness, and risk management. The role focuses on... ...The GRC Security Compliance Specialist works closely with cybersecurity...Temporary workWork at officeLocal areaRemote workFlexible hours$90k - $115k
...restrictions. Our Senior Security Policy Analyst is... ...ServiceNow to streamline policy management, compliance tracking, and reporting... ...experience in governance, risk, and compliance (GRC) operations, and excels at... ...Like to collaborate with IT, Risk, Compliance, and...Full timeContract workFor contractorsWork at officeLocal areaImmediate startRemote work3 days per week- ...employees Job Description The Director of (Cyber) Security Architecture and Engineering is a cyber leadership role... ...business strategy, technology transformation, and enterprise risk management objectives. This role provides strategic and hands-on leadership...Live inWork at officeWork from homeFlexible hours
- ...engineering, operations management, and technology to... ...response, and the Microsoft security suite. This role... ...to identify potential risks and vulnerabilities relevant... ...performance. Collaborate with IT and other departments... ...tracking tools, GRC platforms, and project...Permanent employmentFull timeContract work
- ...A leader in technology and integration services is seeking an AUTOSAR Developer, Engineer, or Security Specialist for remote work. The role requires knowledge of AUTOSAR Classic and proficiency in C programming, alongside good English language skills (B2 level). With a...Remote work
- ...Job Title & Location Position: IT Security Analyst II Work Environment:... ...security governance, risk, and compliance programs through... ...Governance, Risk, and Compliance (GRC) program in alignment with... ...remediation tracking, exception management, and control validation...Contract workWork at officeRemote workFlexible hours
$21.75 - $23 per hour
...Security Supervisor Apply now and take the first step toward a rewarding career with Securitas... ...USA: With over 640 local branch managers and approximately 86,000 security officers... ...guarding, remote guarding, and corporate risk management. Securitas is committed to...Weekly payFull timeLocal areaRemote workShift workNight shiftWeekend workDay shiftAfternoon shift$30 - $33 per hour
...The Security Systems Specialist is responsible for all aspects of planning, facilitation, management and delivery of electronic and cloud-based security... ...in coordination with IT to keep devices operational... ...based incident management and GRC platforms. Knowledge of data...Hourly payFor contractorsWork experience placementWork at officeLocal areaRemote work$120k - $140k
...for the Consultant - Endpoint Security Analyst role at Kalles Group... ...approach to Patch Management across their organization. This... ...Business Systems Analyst role within IT operations, ideally with exposure... ...Staff Cyber Security Engineer - GRC (REMOTE) Seattle, WA $85,000...Full timeRemote workFlexible hours- ...We are seeking an experienced SAP Security & GRC Consultant with 10 years of expertise. The... ...for designing SAP security architecture, managing roles and authorizations, implementing SAP... ...Security SAP GRC Role Design Risk Analysis Preferred Skills: ~ S/4...Remote work
$55 - $60 per hour
...from Akkodis Sr. Recruiter - GRC (Global Recruitment Center) at... ...Akkodis is seeking an IT Security Analyst for a Contract position... ...modelling; as well as institute risk detection and risk mitigation... ...of AWS security and network management tools and resources. Strong background...Contract workTemporary workWork experience placementLocal areaRemote workEarly shift- A technology solutions company is seeking a remote SAP Security Analyst. The role involves troubleshooting SAP security, supporting projects... ...concepts. Candidates should have experience with SAP security, GRC access control, and S/4 Hana, along with excellent communication...Remote job
$185k - $296k
...Manager, Security Operations San Francisco, CA • New York, NY • United States Figma is growing... ...Engineering, Platform Security, IT, GRC, and Legal to strengthen our detection... ...or FedRAMP requirements Applied AI risk management frameworks such as NIST AI RMF...Full timeRemote workWork from home- ...Senior Information Security Analyst Wilmington,... ...Information Technology Risk Oversight (ITRO) function... ...its dynamic second-line IT risk oversight team with... ...component of the broader Risk Management and Governance... ...remediated in CSC global GRC tool. Participate...Local areaRemote workWorldwideMonday to Friday
$180k - $219k
Director of Engineering, Security This role will be based... ...executive briefings on risk posture. Build a high-performing... ...optimize licensing, and manage vendor success.... ...engagement across Engineering, IT, Data, Product, Legal/... ...intel (MISP/OpenCTI); GRC (Drata/Vanta/ServiceNow)...Full timeWork at officeRemote work3 days per week- SAP S4 GRC Security Consultant Remote Job - United States | Posted - 03/24/23 Apply Easy Apply Hi, Hope you are doing... ...Thanks & Regards, Rakhi Jha Client Relationship Manager United Software Group, Inc. End-to-End IT Systems | Services | Solutions Provider A Minority...Long term contractLocal areaRemote work
- A consulting firm is seeking a SAP S4 GRC Security Consultant for a long-term contract. This remote position will involve configuring SAP GRC security and defining roles and authorization design. The ideal candidate must have extensive SAP GRC security implementation experience...Remote jobLong term contract
$300k
...regulatory frameworks Deliver practical, solution-oriented counsel directly to clients while identifying and mitigating tax-related risks Draft comprehensive joint venture agreements on behalf of developers across diverse real estate projects What sets this role...Full timeLocal areaRemote work- Phase2 Technology in Austin, TX is seeking an Information Technology Coordinator I to lead physical security projects. You will coordinate installation requirements and work closely with campus entities to enhance security across the university. The position offers flexible...Remote jobFlexible hours
$212k - $230k
...technology company in the United States is seeking a Director of Governance, Risk, and Compliance (GRC) to define and execute security governance strategies. This role requires strong expertise in managing compliance, overseeing third-party risks, and leading audits. The...Remote work
Do you want to receive more vacancies?
Subscribe and receive similar vacancies to Security GRC Specialist, IT/Security Risk Management. Be the first to apply!
- network security consultant Remote
- security consultant Remote
- senior information security analyst Remote
- security coordinator Remote
- security specialist Remote
- security advisor Remote
- entry level information security analyst Remote
- work from home security analyst Remote
- security analyst remote Remote
- security systems specialist Remote




